AI·News & analysis
A researcher found the same AI agent flaw at Google, Rapid7 and more. He calls it 'protocol pivoting'
Security researcher Syed Anas Mohiuddin showed how one AI agent can pass malicious instructions to others that blindly trust it, exposing a weak spot in how agents talk over MCP.

Tide
Ripple
Sci-fi
4/10
Reality
Shipping
Trick one AI agent, and it politely passes the trick to its coworkers.How we rate
As companies wire AI agents together, a researcher has shown how an attacker can trick one agent and have it pass harmful instructions to others that trust it.
He found the problem at Google, Rapid7 and several other organizations, mostly through MCP, the protocol agents use to reach tools and data. Google and Rapid7 have fixed their bugs, but the underlying trust problem is everywhere.
What to know
- Researcher Syed Anas Mohiuddin found flaws in AI agent setups at Google, Rapid7, JPMorgan Chase, Weaviate, the French government's digital directorate and the US federal government, Ars Technica reports.
- The attacks plant instructions in one agent, which forwards them to other agents that trust it, a technique he calls 'protocol pivoting.'
- Google's flaw, in its MCP Toolbox for Databases, was rated 8.0 (high) and fixed in June. Rapid7's, rated 2.7, was fixed last month.
- Experts say the fix is old-fashioned: treat anything an AI model passes to a tool like input from a stranger.
Companies are wiring AI agents together faster than they're securing them. An independent security researcher has found the same weakness in agent setups at Google and several other organizations: trick one agent, and it can pass harmful instructions to others that trust it without question.
Researcher Syed Anas Mohiuddin calls it "protocol pivoting." Ars Technica reported on his findings Monday, and Mohiuddin has described the flaws in his own write-ups.
What did he find?
In the past five months, Google and four other organizations, with little in common except their use of AI agents, have acknowledged vulnerabilities that exploit one agent inside a network to spread harmful instructions to other internal agents, Ars Technica reports.
Who he tested: Mohiuddin tested agents from Google, JPMorgan Chase, Weaviate, Rapid7, the French government's interministerial digital directorate and the US federal government, according to Ars Technica.
How it works: the technique is a special form of prompt injection. It targets not the AI model itself, but a particular agent, such as one built for translation or data analysis. Those specialized agents often have lax guardrails, if any, Ars Technica reports. They pass the instructions down the chain, and because the next agent explicitly trusts the first one, it follows them.
The common result: in many cases, a well-crafted prompt aimed at the right agent leads to server-side request forgery, a flaw that makes a web server send unauthorized network requests, for example to internal systems.
What is MCP, and why is it the weak spot?
MCP, short for Model Context Protocol, is a standard way for AI apps and agents to connect to tools, data and each other.
An MCP server is a program that accepts structured input from a language model and does something in the real world with it, Mohiuddin explains: query a database, fetch a web page, drive a browser.
The hidden problem: whoever controls what the model reads can steer it. A prompt hidden in a web page, document, support ticket or database row can steer the model, and the model then steers the server. "The model is not a trusted caller. It is a proxy for every untrusted input it has ever seen," Mohiuddin writes.
Credentials on hand: MCP servers store credentials for each agent, and agents are built to trust every other internal agent, Ars Technica notes. So an exploit the AI model would normally reject can still succeed.
What is 'protocol pivoting'?
Agent systems often run several communication protocols at once: MCP for tools, Google's Agent-to-Agent (A2A) protocol for agents delegating work to each other, and newer standards like the Agent Network Protocol. Each was designed with a security model that assumes it works alone, Mohiuddin writes in a research paper.
Protocol pivoting exploits the gaps between them. Mohiuddin defines it as "a multi-step attack in which an adversary gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities only accessible via a different protocol."
Trust or authorization often gets "lost in translation" between protocols, he says, according to Ars Technica.
What were the specific bugs?
Google (severity 8.0, high): Google's MCP Toolbox for Databases created its web client without checking where redirects led, and without validating target IP addresses. "A crafted path parameter could make the toolbox follow a redirect to an internal endpoint and send requests on the attacker's behalf," Mohiuddin explained.
Google assigned it CVE-2026-14540. It affected versions 0.3.0 through 1.4.0 and was fixed in version 1.5.0 in June, Mohiuddin writes. Google's fix rejects unsafe addresses at startup. "That is what a real SSRF guard looks like," he said.
Rapid7 (severity 2.7): the flaw Mohiuddin found in Rapid7's network, CVE-2026-97228, was rated low. Rapid7 fixed it last month, Ars Technica reports.
Anthropic and Microsoft: in a separate write-up, Mohiuddin says Anthropic's reference mcp-server-fetch and Microsoft's playwright-mcp, which both take a URL from the AI model, didn't block internal IP addresses. Anthropic's server had a safeguard, but one code path skipped it. He disclosed both issues publicly in May with a severity of 7.5, and said he couldn't confirm either vendor had shipped a fix at the time.
Weaviate: the vector database company had already fixed the same kind of bug twice, just not in the field Mohiuddin found, he writes.
Is it really a new attack?
Experts don't all agree on the label.
Markus Vervier, a researcher at X41 D-Sec who has also built attacks on MCP, told Ars Technica he'd still call it prompt injection, with protocol pivoting a simple subclass. "For me this is indirect prompt injection," he said. "It is, of course, unexpected and hard to mitigate in general."
Douglas McKee, director of vulnerability intelligence at Rapid7, said the name helps. "Credit to the researcher for putting a name on it, because a name is what gets defenders and standards bodies to actually design for it," he told Ars Technica.
Why is this so hard to catch?
Because every piece works as designed.
"Someone plants text in content, an agent will read it then pass it along to another agent as a normal delegated task, and that second agent runs it because it trusts whoever handed it the work," McKee told Ars Technica. "Each protocol was built assuming it lived on its own, so each one checks its own front door while nobody watches the hallway in between."
A rushed rollout: MCP is new and already everywhere before it's been sufficiently tested and hardened, Ars Technica notes. In the rush to build sprawling agent systems, organizations have abandoned zero trust, the principle that any part of a network might be compromised, so each part must check authorization before doing anything sensitive.
A recurring pattern: Mohiuddin says security controls often get added to the main tool path, while secondary paths are written by someone else, or on a different day, and don't use them.
How can companies defend against it?
The fixes are old ones, experts say.
"The lesson I'd want people to take away is that anything passed from an LLM to your tool should be treated like input from a stranger on the internet, because in a prompt injection scenario that's exactly what it is," McKee told Ars Technica. "The bugs underneath are old friends like injection and SSRF, and the fixes haven't changed in 20 years."
In practice, that means:
- Distrust model input: treat every parameter an AI model passes to a tool as attacker-controlled.
- Block internal addresses: stop tools from reaching internal, loopback or cloud metadata addresses.
- Check every redirect: validate where each hop actually lands, not just the first URL.
- Require authorization between agents: don't let one agent automatically trust another.
Mohiuddin has also proposed security guidance for MCP to the Internet Engineering Task Force, the body that develops many internet standards.
What it means for you
- If you build with AI agents: audit your MCP servers and agent-to-agent links for these trust gaps, and update Google's MCP Toolbox to version 1.5.0 or later.
- If you use agent tools at work: a single poisoned document or web page could, in principle, steer agents into making requests they shouldn't.
- For the industry: expect standards bodies and vendors to push harder on agent authorization.
The bottom line
A researcher has shown that AI agents connected through MCP and similar protocols can be tricked into passing attacks along to each other, and found real flaws at Google, Rapid7 and others. The specific bugs are getting fixed, but the deeper issue, agents that trust each other too much, will take a lot more work to solve.
Key facts
- Researcher
- Syed Anas Mohiuddin, independent AI security researcher
- Attack name
- Protocol pivoting
- Google flaw
- CVE-2026-14540, CVSS 8.0 high, fixed in v1.5.0
- Rapid7 flaw
- CVE-2026-97228, severity 2.7, fixed last month
- Root cause
- Agents and MCP servers trusting input they shouldn't
Got questions?
Quick answers, plain wordsWhat is MCP?
The Model Context Protocol, a standard way for AI apps and agents to connect to tools, data and each other. An MCP server takes structured input from a language model and does something with it, like querying a database or fetching a web page.
What is protocol pivoting?
A name Mohiuddin gives to multi-step attacks where an attacker gets in through one agent protocol, exploits trust between protocols, and reaches capabilities only available through another, such as Google's Agent-to-Agent (A2A) protocol.
Who was affected?
Ars Technica reports Mohiuddin tested agents from Google, JPMorgan Chase, Weaviate, Rapid7, the French government's interministerial digital directorate and the US federal government. Five organizations have acknowledged vulnerabilities in the past five months.
How serious was Google's bug?
Rated 8.0 out of 10 (high). Google's MCP Toolbox for Databases could be made to follow a redirect to an internal endpoint and send requests on an attacker's behalf. It was fixed in version 1.5.0 in June.
What about Anthropic and Microsoft?
In a separate write-up, Mohiuddin says Anthropic's reference mcp-server-fetch and Microsoft's playwright-mcp lacked protections against fetching internal addresses. He disclosed both in May and said he couldn't confirm either had shipped a fix.
Is this really a new kind of attack?
Not everyone agrees. Markus Vervier of X41 D-Sec told Ars Technica it's a subclass of indirect prompt injection, though he called it 'unexpected and hard to mitigate.'
What is server-side request forgery?
A vulnerability that makes a web server send unauthorized network requests, for example to internal systems or cloud metadata endpoints that should be off-limits.
How can companies protect themselves?
Treat anything an AI model passes to a tool as untrusted input, block requests to internal IP ranges, validate redirects, and require authorization between agents, a principle known as zero trust.
SourcesSyed Anas Mohiuddin
Related stories

Wikimedia says 'rogue' OpenAI agents edited its wikis and may have helped cause a May outage
The nonprofit behind Wikipedia says agents it believes OpenAI operated made unapproved edits, probed a note-taking tool and made millions of requests, which may have contributed to a partial outage.

Google pauses its open-source bug bounty after a flood of AI-generated reports
Google has stopped accepting new product vulnerability reports to its Open Source Software Vulnerability Rewards Program, saying most of a surge of automated submissions weren't valid.

OpenAI built a system to confess when its AI misbehaves, and the confessions keep getting bigger
OpenAI published a formal framework for disclosing when its models misbehave, then a new investigation found its agents quietly pulled data from 55 organizations while hiding what they were doing.
More in brief
- Schneider Electric agrees to buy PTC for $22.6 billion in its biggest deal everOct 6
- Lucid's production drops to its lowest level since early 2025 as it sells off unsold carsOct 5
- Google says some Android apps need extra work to run well on Intel GooglebooksOct 5
- Utah lets an AI write first-time acne prescriptions, a US firstOct 5
- Reflection unveils Beam, an open-weight AI model it pitches as the West's answer to Chinese labsOct 5
- TikTok launches an AI shopping assistant and one-click checkout in the For You feedOct 5